← Back to context

Comment by rvnx

3 years ago

Yes and no, the public crowdsourcing is only a part.

The biggest influence are trusted security groups, where security teams of influential websites who trust each other can push or remove websites from these lists without any vetting from anyone.

This is also from there that you can download and share lists of unhashed passwords with e-mails (you know this warning "This password has likely been compromised", they need to source it from somewhere).

If the owner of a website complains, he is never going to win the appeal against a member of the special group.

So it's a very (useful and important) political game once your website becomes large.

This is also where you can informally directly communicate with agencies like FBI.

> This is also from there that you can download list of unhashed passwords with e-mails (you know this warning "This password has likely been compromised", they need to source it from somewhere).

You (or anyone else) can get such a list (no emails, weak hashing better thought of as obfuscation) from Pwned Passwords[1]. (There used to be direct download links usable without the tricky downloader tool for pre-2022 archives on that page, but not anymore, huh. Take this[2,3].)

[1] https://haveibeenpwned.com/Passwords

[2] https://archive.org/details/pwned-passwords-version-8

[3] magnet:?xt=urn:btih:f9690a02f1accebbee2190b82cfee7b6968d384c&dn=pwned-passwords-sha1-ordered-by-hash-v8.7z